Earth Bogle is an unattributed, Arabic-speaking campaign cluster documented by Trend Micro that distributes the commodity njRAT to Middle Eastern and North African victims using geopolitical- and religious-themed lures delivered via abused public cloud and hosting services.
Earth Bogle is Trend Micro's designation for an ongoing malware operation, active since at least mid-2022 and detailed in January 2023, that spreads the commodity remote-access trojan njRAT across the MENA region. No state sponsor has been established; the operator is assessed only as Arabic-speaking and financially or opportunistically motivated, making sponsor attribution low confidence while the activity itself is well documented — a distinction the campaign's inclusion here deliberately preserves.
The campaign's tradecraft is notable less for sophistication than for scale and social engineering. Operators use geopolitical and Islamic religious themes as lures — including content referencing regional sensitivities — packaged in malicious files that ultimately deploy njRAT, giving remote control, keylogging, credential theft, and file access. To host payloads and lures the actor abuses legitimate public-cloud and file-hosting infrastructure (including cloud storage and compromised or free hosting), and uses DNS-service abuse to obscure its infrastructure, lowering cost and complicating takedown.
Targeting is broad and opportunistic across the Middle East and North Africa's Arabic-speaking user base rather than a narrow high-value victim set, spanning multiple sectors and individual users. This mass, low-cost model contrasts with the deliberate victimology of state espionage clusters and is more consistent with a commodity-RAT operation exploiting regional political tensions for lure resonance.
Earth Bogle's last independently confirmed reporting is Trend Micro's January 2023 publication; the njRAT tooling and lure themes remain in wide regional use, but no distinct Earth Bogle-branded activity has been prominently re-reported into 2025–2026.